Privacy policy
Your terminal is yours.
Shelly connects your Android phone to terminal sessions running on your computer. It does not require an account, sell personal data, or use terminal content for advertising or analytics.
The short versionTerminal input and output travel through encrypted connections between your paired devices. Shelly's relay and push systems never receive terminal text, keystrokes, commands, file paths, or session names.
01
Information Shelly handles
Shelly handles only the information needed to connect and operate the app:
- Pairing and device information. Device public identifiers, encrypted device credentials, relay or direct network addresses, and a short-lived pairing code.
- Push identifiers. If notifications are enabled, an FCM registration token and Firebase installation identifier are used to deliver generic notifications. Core terminal features work without push notifications.
- Connection metadata. Network infrastructure necessarily processes IP addresses, timing, and byte counts to route encrypted traffic. Shelly does not add this information to product analytics.
02
Information Shelly does not collect
Shelly infrastructure cannot read the terminal content exchanged by your paired devices. It does not collect terminal output, keystrokes, commands, file paths, session names, contacts, location, photos, audio, financial information, or advertising identifiers.
QR camera frames are processed on your phone for pairing and are not uploaded. Biometric verification is performed by Android; Shelly never receives or stores your biometric data.
03
How information is used
Information handled by Shelly is used only to:
- pair your phone with a computer you approve;
- connect, display, and control your terminal sessions;
- deliver generic notifications when a session needs attention;
- prevent abuse, replay, and unauthorized pairing attempts; and
- maintain the security and reliability of Shelly's relay service.
04
Service providers and sharing
Shelly does not sell personal data, show ads, or share data with data brokers. Google Firebase Cloud Messaging processes push identifiers when notifications are enabled. Hosting and network providers may process limited connection information to operate Shelly's infrastructure. These providers act only to deliver their services to Shelly.
Push messages contain fixed generic text, an event type, and an opaque session hash. They never contain terminal output, commands, paths, or session names.
05
Storage and retention
- Pairing codes expire after five minutes and are consumed after successful use.
- Pairing records and queued push identifiers are encrypted in app-private storage and removed when you unpair or clear the app's data.
- Relay push-token bindings remain only while needed to deliver notifications and are removed when a device is unpaired, revoked, or deleted on request.
- Terminal scrollback remains on your computer and is encrypted locally when persistence is enabled.
06
Your choices and deletion
You can disable notifications in Shelly or Android, unpair your phone, revoke a paired device from your computer, clear the app's storage, or uninstall the app. Shelly has no user accounts.
To request removal of a relay-side push identifier or ask a privacy question, email jigyanshu15@gmail.com. Include enough information to identify the paired device, but never send terminal content, secrets, or private keys.
07
Security
Shelly uses encrypted transport between paired devices, encrypted local pairing records, short-lived pairing codes, OS-protected key material, and Android's biometric gate. No security measure can eliminate every risk, so you should keep your phone and computer updated and revoke devices you no longer use.
08
Age limits and policy changes
Shelly is intended for adults and is not directed to children under 18. We may update this policy when the product or legal requirements change. The effective date at the top of this page will identify the latest version.